Keeping WordPress secure means staying alert to new plugin vulnerabilities. This week, several notable threats were disclosed, including a critical CSRF flaw in Avada Core.
CSRF attacks rely on trust, so learn how to recognise the risk and stay protected. (see below)
#1 – Critical Security Risks in Popular Plugin
This plugin could allow a higher privileged users to execute unwanted actions under their current authentication.
Avada Core Plugin
CSRF; 9.6/10; Update to v5.15.7+; Recurring 2×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#2 – Other Security Risks in Popular Plugins
Millions of sites use the plugins below, and two vulnerabilities still remain unpatched.
Payment Plugins for Stripe WooCommerce Plugin
Broken Access Control; 7.5/10; Update to v4.0.8+
Hide My WP Ghost Plugin
Broken Authentication; 7.4/10; Update to v7.0.07+; Recurring 2×
Complianz Plugin
PHP Object Injection; 7.2/10; No fix; Remove/or replace.
MailPoet Plugin
CSRF; 7.1/10; Update to v5.33.1+
Contact Form 7 – Dynamic Text Extension Plugin
Content Injection; 6.5/10; No fix; Remove/or replace.
Orbit Fox by ThemeIsle Plugin
XSS; 5.9/10; Update to v3.0.8+
WP Activity Log Plugin
CSRF; 5.4/10; Update to v5.6.5+; Recurring 2×
WP Go Maps Plugin
Broken Access Control; 5.3/10; Update to v10.1.06+; Recurring 4×
Event Tickets Plugin
Broken Access Control; 5.3/10; Update to v5.29.1+; Recurring 3×
GutenKit Plugin
Broken Access Control; 5.3/10; Update to v2.4.13+
Polylang Plugin
Sensitive Data Exposure; 4.3/10; Update to v3.8.6+
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#3 – High Security Risks in Less Popular Plugins
These plugins may be less common, but the potential damage is significant.
Participants Database Plugin
Arbitrary File Deletion; 10/10; Update to v2.7.8.4+
Advanced Views Plugin
RCE; 9.9/10; Update to v3.9.0+
Thrive Quiz Builder Plugin
PHP Object Injection; 9.8/10; Update to v10.9.3.1+
SMS Alert Order Notifications Plugin
Privilege Escalation; 9.8/10; Update to v3.9.7+; Recurring 3×
rtMedia for WordPress, BuddyPress and bbPress Plugin
SQL Injection; 9.3/10; Update to v4.7.11+
GamiPress Plugin
SQL Injection; 9.3/10; Update to v7.9.8+
Lumise Product Designer Plugin
SQL Injection; 9.3/10; Update to v2.1.2+; Recurring 2×
AWP Classifieds Plugin
SQL Injection; 9.3/10; Update to v4.4.8+; Recurring 2×
MapSVG Plugin
SQL Injection; 9.3/10; Update to v8.14.1+; Recurring 2×
Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.
#4 – Our blog: Detecting and Preventing WordPress CSRF Vulnerabilities
Fix ‘No anti-CSRF tokens found’ WordPress warnings. Learn why nonces protect forms, test vulnerabilities in minutes, and implement proper validation.
Thanks for reading, and have a wonderful week!
Paul Goodchild
Shield Security for WordPress